Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange ox app suite 7.10.5 vulnerabilities and exploits
(subscribe to this query)
312
VMScore
CVE-2021-38374
OX App Suite through up to and including 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
Open-xchange Ox App Suite
383
VMScore
CVE-2021-38375
OX App Suite up to and including 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
Open-xchange Ox App Suite
445
VMScore
CVE-2021-38376
OX App Suite up to and including 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
Open-xchange Ox App Suite
383
VMScore
CVE-2021-38377
OX App Suite up to and including 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
Open-xchange Ox App Suite
383
VMScore
CVE-2021-33489
OX App Suite up to and including 7.10.5 allows XSS via JavaScript code in a shared XCF file.
Open-xchange Ox App Suite
383
VMScore
CVE-2021-33490
OX App Suite up to and including 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
Open-xchange Ox App Suite
320
VMScore
CVE-2021-33493
The middleware component in OX App Suite up to and including 7.10.5 allows Code Injection via Java classes in a YAML format.
Open-xchange Ox App Suite
516
VMScore
CVE-2021-33488
chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
Open-xchange Ox App Suite
356
VMScore
CVE-2021-33491
OX App Suite up to and including 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
Open-xchange Ox App Suite
NA
CVE-2022-31469
OX App Suite up to and including 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »